Governance SPICE. Using COSO and COBIT Process Assessment Models BPM GOSPEL

Size: px
Start display at page:

Download "Governance SPICE. Using COSO and COBIT Process Assessment Models BPM GOSPEL"

Transcription

1 Governance SPICE Using COSO and COBIT Process Assessment Models Linking Governance to Sustainable Value Creation BPM GOSPEL (LLP-LDV-TOI-2010-HU-001) This project has been funded with support from the European Commission. This publication reflects the views only of the authors, and the Commission cannot be held responsible for any use which may be made of the information contained therein. János Ivanyos Memolux Ltd. Dr. József Roóz Budapest Business School

2 Topics Governance SPICE ( ) COBIT/COSO Performance Measurement Governance Capability - Mapping COSO Objectives with ISO/IEC Capability Levels COSO & COBIT as Process Reference Models Linking Governance to Sustainable Value Creation Governance Model for Trusted Businesses Multi-layer business assurance technology Developing case studies for learning and coaching SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

3 Governance SPICE ( ) Refers to Governance, Risk and Controls (OECD Principles, Regulations, Audit Standards) based on different concepts (IA-Manager ) Recognized Control Frameworks (COSO&COBIT) Risk Tolerance and Risk Appetite (COSO ERM) Performance Measurement (COBIT) Process Capability Assessment (ISO/IEC ) Evaluating Process-related Risk (ISO/IEC ) Organizational Maturity (ISO/IEC TR ) by using multilingual ontology (MONTIFIC ) Terminology database Ontology model to leverage sustainable value creation (GOSPEL ) Governance Model for Trusted Businesses Multi-layer business assurance technology SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

4 Validation of Governance SPICE Competencies Governance, Risk and Controls SPICE Audit SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

5 Using COSO & COBIT Process Assessment Models Measurement Framework COSO Objective Categories COBIT Performance Drivers Risk Tolerance Risk Appetite Strategic high-level goals, aligned with and supporting entity s mission Operations effective and efficient use of entity s resources Reporting reliability of reporting Compliance compliance with applicable laws and regulations COSO 20 Control Processes Strategic Goals drivenby the outcome measures of Established IT processes Effective and efficient business operation driven by the outcome measures of Managed IT Processes Reliable IT operation driven by the outcomemeasures of Performed IT Processes IT Goals driven by the outcome measures of IT Activities COBIT 34 ITGC Processes GOVERNANCE SPICE Business Processes Financial Reporting Activities Business Process Models SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

6 Business goals Maintain enterprise reputation and leadership Number of incidents causing public embarrassment COBIT IT goals Ensure that IT services can resist and recover from attacks Number of actual IT incidents with business impact driven by Process goals Activity goals focusing on achieved by Understand security requirements, vulnerabilities and threats Detect and resolve unauthorised access Frequency of review of the type of security events to be monitored driven by Number of actual incidents because of unauthorised access driven by COBIT Performance Measurement 6

7 Evidencies Focusing on Objectives categories Assessments Effectiveness goals Strategic COSO Objectives Metrics Efficiency goals Organizational levels Policies Standardization goals Operations Procedures Deployment goals Workprograms Workproducts Management goals Documentation goals Reporting Operational levels Operational levels Activities Process goals Compliance 7

8 Evidencies Focusing on Objectives categories Assessments Effectiveness goals Strategic COSO Objectives Metrics Efficiency goals Organizational levels Policies Standardization goals Procedures Deployment goals Operations Outcome measures Workprograms Management goals Reporting Operational levels Workproducts Documentation goals Operational levels Activities Process goals Compliance 8

9 Evidencies Focusing on Objectives categories Assessments Effectiveness goals Strategic COSO Objectives Metrics Efficiency goals Organizational levels Policies Standardization goals Procedures Deployment goals Operations Performance drivers Workprograms Management goals Reporting Operational levels Workproducts Documentation goals Operational levels Activities Process goals Compliance 9

10 Strategic COSO OBJECTIVES high-level goals, aligned with and supporting entity s mission processes consistently enactedwithin defined limits COSO ERM Internal Control define driven by Operations effective and efficient use of entity s resources defined processes used based on standard process Level 3 Established are based on reliable Reporting are achieved by performing Compliance compliance with applicable laws and regulations reliability of reporting implemented processes achieving process purpose driven by mananged managed processeswith established, controlled and maintained work products Level1 Performed driven by Level 2 Managed ISO/IEC CAPABILITY LEVELS 10

11 ISO/IEC Capability Levels The process is continuously improved to meet relevant current and projected business goals. Level 5 Optimizing process PA 5.1 Process Innovation PA 5.2 Process Optimization The process is enacted consistently within defined limits. Level 4 Predictable process PA 4.1 Process Measurement PA 4.2 Process Control A defined process is used based on a standard process. Level 3 Established process PA 3.1 Process Definition PA 3.2 Process Deployment Level 2 Managed process PA 2.1 Performance Management PA 2.2 Work Product Management The process is managed and work products are established, controlled and maintained. Level 1 Performed process PA 1.1 Process Performance The process is implemented and achieves its process purpose. Level 0 Incomplete process The process is not implemented or fails to achieve its purpose. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

12 ISO/IEC Capability Levels and COSO The process is continuously improved to meet relevant current and projected business goals. Level 5 Optimizing process PA 5.1 Process Innovation PA 5.2 Process Optimization STRATEGIC The process is enacted consistently within defined limits. Level 4 Predictable process PA 4.1 Process Measurement PA 4.2 Process Control COSO A defined process is used based on a standard process. RELIABLE REPORTING Level 3 Established process PA 3.1 Process Definition PA 3.2 Process Deployment Level 2 Managed process PA 2.1 Performance Management PA 2.2 Work Product Management OPERATIONS The process is managed and work products are established, controlled and maintained. Level 1 Performed process PA 1.1 Process Performance The process is implemented and achieves its process purpose. COMPLIANCE Level 0 Incomplete process The process is not implemented or fails to achieve its purpose. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

13 ISO/IEC Capability Levels and COBIT The process is continuously improved to meet relevant current and projected business goals. Level 5 Optimizing process PA 5.1 Process Innovation PA 5.2 Process Optimization STRATEGIC GOALS The process is enacted consistently within defined limits. Level 4 Predictable process PA 4.1 Process Measurement PA 4.2 Process Control COBIT A defined process is used based on a standard process. RELIABILITY GOALS Level 3 Established process PA 3.1 Process Definition PA 3.2 Process Deployment Level 2 Managed process PA 2.1 Performance Management PA 2.2 Work Product Management BUSINESS GOALS The process is managed and work products are established, controlled and maintained. Level 1 Performed process PA 1.1 Process Performance The process is implemented and achieves its process purpose. IT GOALS Level 0 Incomplete process The process is not implemented or fails to achieve its purpose. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

14 Mapping Objectives Outcome Measures with Capability Levels Level 4 Predictable process PA 4.1 Process Measurement PA 4.2 Process Control Level 3 Established process PA 3.1 Process Definition PA 3.2 Process Deployment Level 2 Managed process PA 2.1 Performance Management PA 2.2 Work Product Management Level 1 Performed process PA 1.1 Process Performance SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

15 Terminology Mapping ISO/IEC COSO COBIT Process Category Component Domain Process Principle Process Process Name Principle name Process name Process Purpose Principle description IT goal Process Outcome Attribute Activity goal Base Practice Approach Control Objective Work Product - Input/Output SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

16 COBIT processes Plan and Organize (PO) PO1 Define a Strategic IT Plan PO2 Define the Information Architecture PO3 Determine Technological Direction PO4 Define the IT Processes, Organisation and Relationships PO5 Manage the IT Investment PO6 Communicate Management Aims and Direction PO7 Manage IT Human Resources PO8 Manage Quality PO9 Assess and Manage IT Risks PO10 Manage Projects Acquire and Implement (AI) AI1 Identify Automated Solutions AI2 Acquire and Maintain Application Software AI3 Acquire and Maintain Technology Infrastructure AI4 Enable Operation and Use AI5 Procure IT Resources AI6 Manage Changes AI7 Install and Accredit Solutions and Changes Deliver and Support (DS) DS1 Define and Manage Service Levels DS2 Manage Third-party Services DS3 Manage Performance and Capacity DS4 Ensure Continuous Service DS5 Ensure Systems Security DS6 Identify and Allocate Costs DS7 Educate and Train Users DS8 Manage Service Desk and Incidents DS9 Manage the Configuration DS10 Manage Problems DS11 Manage Data DS12 Manage the Physical Environment DS13 Manage Operations COSO processes Control Environment (CE) Integrity and Ethical Values (IEV) Oversight Board (OB) Management s Philosophy and Operating Style (MPO) Organizational Structure (OS) Financial Reporting Competencies (FRC) Authority and Responsibility (AR) Human Resources (HR) Risk Assessment (RA) Financial Reporting Objectives (FRO) Financial Reporting Risks (FRR) Fraud Risk (FR) Control Activities (CA) Integration with Risk Assessment (IRA) Selection and Development of Control Activities (SD) Policies and Procedures (PD) Information Technology (IT) Information and Communication (IC) Financial Reporting Information (FRI) Internal Control Information (ICI) Internal Communication (IC) External Communication (EC) Monitoring (MO) Ongoing and Separate Evaluations (OSE) Reporting Deficiencies (RD) Monitor and Evaluate (MO) ME1 Monitor and Evaluate IT Performance ME2 Monitor and Evaluate Internal Control ME3 Ensure Compliance With External Requirements ME4 Provide IT Governance 16

17 COSO-based Process Assessment Model SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

18 ISO/IEC conform process definition of a COSO Principle Process ID IFC.CE.IEV Process Name Integrity and Ethical Values Process Purpose Sound integrity and ethical values, particularly of top management, are developed and understood and set the standard of conduct for financial reporting. Process As a result of successful implementation of IFC.CE.IEV process: Outcomes 1) Values articulated Top management develops a clearly articulated statement of ethical values that is understood at all levels of the organization. 2) Adherence monitored Processes are in place to monitor adherence to principles of sound integrity and ethical values. 3) Deviation addressed Deviations from sound integrity and ethical values are identified in a timely manner and appropriately addressed and remedied at appropriate levels within the organisation. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

19 ISO/IEC conform base practice descriptions from COSO SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

20 ISO/IEC conform definition of a COBIT process Control over the IT process of Define a strategic IT plan that satisfies the business requirement for IT of by focusing on is achieved by Process sustaining or extending the business strategy and governance requirements whilst being transparent about benefits, costs and risks incorporating IT and business management in the translation of business requirements into service offerings, and the development of strategies to deliver these services in a transparent and effective manner Engaging with business and senior management in aligning IT strategic planning with current and future business needs Understanding current IT capabilities Providing for a prioritisation scheme for the business that quantifies the business requirements Purpose Related Practices Outcomes and is measured by Percent of IT in the IT strategic plan that support the strategic business plan Percent of IT projects in the IT project portfolio that can be directly traced back to the IT tactical plans Delay between updates of IT strategic plan and updates of IT tactical plans SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

21 COBIT PAM (Exposure Draft 12 Apr 2011) SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

22 Linking Governance to Sustainable Value Creation??? SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

23 Setting Governance Objectives Supporting Organization s Internal Control System Risk Awareness Accountability Competency Accuracy Process Integrity Data Protection Commitment Control Efficiency Supporting Business Sustainability Competitiveness Exploitability Satisfaction SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

24 Determining Application Process for a Governance Objective (Accuracy) Governance Objective Key Risk Risk Factors Responses Applicable COSO&COBIT processes Application Practices Information architecture is inconsistent with processing requirements Maintaining effective information architecture and data model Define the Information Architecture (COBIT) Satisfy the business requirement of being agile in responding to requirements; provide reliable, consistent information, and seamlessly integrate applications into business processes. 4. Accuracy / Information Reliability Ensured Inconsistency in data architecture and disclosure elements Non-compliance with rules and regulations are not detected in time Availability and quality of control information are not sufficient Information is systematically collected and assessed to detect compliance issues, privacy problems and fraud Control information for automated process settings, data manipulations and calculations are maintained systematically Financial Reporting Information (COSO) Internal Control Information (COSO) Pertinent information is identified, captured, used at all levels of the organisation, and distributed in a form and timeframe that supports the achievement of the organization s financial reporting and trusted business. Information used to execute other control components is identified, captured, and distributed in a form and timeframe that enables personnel to carry out their internal control responsibilities. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

25 Information Reliability Governance Process (Accuracy Objective) Process ID Process Name Process Purpose Process Outcomes GOV.IR Information Reliability The purpose of the Information Reliability process is to ensure the accuracy and consistency in data architecture and disclosure elements relevant for financial reporting and trusted business, and for supporting data processing integrity. NOTE1: The Information Reliability process is a special application of the COSO 2006 and COBIT 4.1 models in the context of the Accuracy governance objective. Thus this process is denoted an Application Area. The practices, called application practices, are implemented using selected processes based on the COSO 2006 principles and the COBIT 4.1 framework in the context of this special application. This facilitates the re-use of the elements of the COSO 2006 and COBIT 4.1 based reference models without recreating processes that are already well established. NOTE2: The descriptions of the COBIT 4.1 processes and the COSO 2006 Principles are applicable to define ISO/IEC conformant process reference models and process performance indicators for assessing process capability according to the ISO/IEC standard. As a result of successful implementation of the Information Reliability process the following service governance are achieved: 1) Effective information architecture and data model are maintained. 2) Information is systematically collected and assessed to detect compliance issues, privacy problems and fraud. 3) Control information for automated process settings, data manipulations and calculations are maintained systematically. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

26 Using Define the Information Architecture COBIT Process as an Application Practice Application practice AP01 Ensure the integrity and consistency of all data stored in electronic form. Satisfy the business requirement of being agile in responding to requirements; provide reliable, consistent information, and seamlessly integrate applications into business processes. [Outcome: 1] NOTE1: This practice is implemented by performing practices (control ) of the COBIT 4.1 Define the Information Architecture process with a specific focus on how governance supports internal control over financial reporting and business operation: PO2.1 Create and maintain enterprise information model. Establish and maintain an enterprise information model to enable applications development and decision-supporting activities, consistent with IT plans. The model should facilitate the optimal creation, use and sharing of information by the business in a way that maintains integrity and is flexible, functional, cost-effective, timely, secure and resilient to failure. PO2.2 Create and maintain enterprise data dictionary (ies). Maintain an enterprise data dictionary that incorporates the organisation s data syntax rules. This dictionary should enable the sharing of data elements amongst applications and systems, promote a common understanding of data amongst IT and business users, and prevent incompatible data elements from being created. PO2.3 Establish and maintain data classification scheme. Establish a classification scheme that applies throughout the enterprise, based on the criticality and sensitivity (e.g., public, confidential, top secret) of enterprise data. This scheme should include details about data ownership; definition of appropriate security levels and protection controls; and a brief description of data retention and destruction requirements, criticality and sensitivity. It should be used as the basis for applying controls such as access controls, archiving or encryption. PO2.4 Manage data integrity. Define and implement procedures to ensure the integrity and consistency of all data stored in electronic form, such as databases, data warehouses and data archives. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

27 Information Reliability - Governance Process using COSO&COBIT Relationship Notes Sources The relationships between the Information Reliability process and application practices, and other processes in COSO 2006 and COBIT 4.1 models, have been noted for each practice above. This innovative concept of including Application Areas in a process assessment model instantiates the idea of using already established processes with respect to a particular application. (Like in Enterprise SPICE) COBIT 4.1: PO2 Define the Information Architecture COSO 2006: IFC.IC.FRI Financial Reporting Information, IFC.IC.ICI Internal Control Information References Control Objectives for Information and related Technology - COBIT 4.1 Copyright 2007 by the IT Governance Institute Algonquin Road, Suite 1010 Rolling Meadows, IL USA. All rights reserved. Internal Control over Financial Reporting Guidance for Smaller Public Companies Copyright 2006 by The Committee of Sponsoring Organization, C/O AICPA, Harborside Financial Center, 201 Plaza Three, Jersey City, NJ , USA. All rights reserved. SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

28 BPM GOSPEL: Multi-layer business assurance technology Concept of 4 layers in BPM GOSPEL: Transaction Processing Memolux Payroll system Workflow/Control Management ADAMAS by GEMMA Ltd. Compliance/Audit Management Stages Governance Edition by Method Park AG Certification Capability Advisor by ISCN SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

29 Using Stages Governance Edition for Compliance/Audit Management SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

30 BPM GOSPEL Case Studies (by end of 2011) Different approaches for demonstrating added business value are considered per industry needs mapping them to Governance, for example: Memolux payroll SOC1&SOC2 Gemma ESF grant management Method Park - Business SPICE for big company BBS - Short Cycle Higher Education ISCN - ECQA Job-role Committee management per (set of) governance Top five based on presentable added values Participation interest from workshop community is welcome! SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

31 Topics covered Governance SPICE ( ) COBIT/COSO Performance Measurement Governance Capability - Mapping COSO Objectives with ISO/IEC Capability Levels COSO & COBIT as Process Reference Models Linking Governance to Sustainable Value Creation Governance Model for Trusted Businesses Multi-layer business assurance technology Developing case studies for learning and coaching More information: Thank you for your attention! SPICE Assessors Workshop Community at the 18th EuroSPI Conference, Roskilde University, Denmark, June

ECQA Certified Profession. Governance SPICE Model. Internal Financial Control Assessor Training Programme

ECQA Certified Profession. Governance SPICE Model. Internal Financial Control Assessor Training Programme ECQA Certified Profession Governance SPICE Model used by the Internal Financial Control Assessor Training Programme Contact: János Ivanyos Memolux Ltd. +36 1 467403 ivanyos@memolux.hu www.training.ia-manager.org

More information

Applying Integrated Assurance Management Scenarios for Governance Capability Assessment

Applying Integrated Assurance Management Scenarios for Governance Capability Assessment Applying Integrated Assurance Management Scenarios for Governance Capability Assessment János Ivanyos Trusted Business Partners Ltd, Budapest, Hungary, ivanyos@trusted.hu Abstract. The well established

More information

CGEIT Certification Job Practice

CGEIT Certification Job Practice CGEIT Certification Job Practice Job Practice A job practice serves as the basis for the exam and the experience requirements to earn the CGEIT certification. This job practice consists of task and knowledge

More information

Translate stakeholder needs into strategy. Governance is about negotiating and deciding amongst different stakeholders value interests.

Translate stakeholder needs into strategy. Governance is about negotiating and deciding amongst different stakeholders value interests. Principles Principle 1 - Meeting stakeholder needs The governing body is ultimately responsible for setting the direction of the organisation and needs to account to stakeholders specifically owners or

More information

Business Context of ISO conform Internal Financial Control Assessment

Business Context of ISO conform Internal Financial Control Assessment Business Context of ISO 15504 conform Internal Financial Control Assessment By János Ivanyos, Memolux Ltd. (H), IIA Hungary Introduction In this paper the business context of the ISO/IEC 15504 [1] conformant

More information

COBIT 5. COBIT 5 Online Collaborative Environment

COBIT 5. COBIT 5 Online Collaborative Environment COBIT 5 Product Family COBIT 5 COBIT 5 Enabler Guides COBIT 5: Enabling es COBIT 5: Enabling Information Other Enabler Guides COBIT 5 Professional Guides COBIT 5 Implementation COBIT 5 for Information

More information

COBIT. IT Governance CEN 667

COBIT. IT Governance CEN 667 COBIT IT Governance CEN 667 1 Project proposal (week 4) Goal of the projects are to find applicable measurement and metric methods to improve processes: For 27000 series of standards 27001 and 27004 For

More information

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010 Catching Fraud During a Recession Through Superior Internal Controls FICPA s 25 th Annual Accounting Show J. Stephen Nouss September 29, 2010 1 Session Objectives Fraud Facts (2008 Association of Certified

More information

COBIT 5. COBIT 5 Online Collaborative Environment

COBIT 5. COBIT 5 Online Collaborative Environment COBIT 5 Product Family COBIT 5 COBIT 5 Enabler Guides COBIT 5: Enabling es COBIT 5: Enabling Information Other Enabler Guides COBIT 5 Professional Guides COBIT 5 Implementation COBIT 5 for Information

More information

September 17, 2012 Pittsburgh ISACA Chapter

September 17, 2012 Pittsburgh ISACA Chapter September 17, 2012 Pittsburgh ISACA Chapter What is COBIT? Control Objectives for Information and related Technologies ISACA s guidance on the enterprise governance and management of IT. Builds on more

More information

IT and Security Governance. Jacqueline Johnson

IT and Security Governance. Jacqueline Johnson IT and Security Governance Jacqueline Johnson Background Control Objectives for Information and related Technology Developed by IT Governance Institute (ITGI) Not incremental High level standard 5 principles

More information

ISO/IEC Process Mapping to COBIT 4.1 to Derive a Balanced Scorecard for IT Governance

ISO/IEC Process Mapping to COBIT 4.1 to Derive a Balanced Scorecard for IT Governance DISCUSS THIS ARTICLE ISO/IEC 27001 Process Mapping to COBIT 4.1 to Derive a Balanced Scorecard for IT Governance By Christopher Oparaugo, CISM, CGEIT, CRISC COBIT Focus 14 December 2015 The balanced scorecard

More information

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance Sharon Hale and John Argodale May 28, 2015 2 From Dictionary.com Enterprise: A project undertaken or to be undertaken, especially one that is important or difficult or that requires boldness or energy

More information

COBIT 5. COBIT 5 Online Collaborative Environment

COBIT 5. COBIT 5 Online Collaborative Environment COBIT 5 Product Family COBIT 5 Enabler Guides : Enabling es : Enabling Information Other Enabler Guides COBIT 5 Professional Guides Implementation for Information for Assurance for Risk Other Professional

More information

Fraud Risk Management

Fraud Risk Management Fraud Risk Management Fraud Risk Management Overview 2017 Association of Certified Fraud Examiners, Inc. Discussion Questions 1. Does your organization follow a specific risk management model? If so, which

More information

APPENDIX O CONTRACTOR ROLES, RESPONSIBILITIES AND MINIMUM QUALIFICATIONS

APPENDIX O CONTRACTOR ROLES, RESPONSIBILITIES AND MINIMUM QUALIFICATIONS APPENDIX O CONTRACTOR ROLES, RESPONSIBILITIES AND MINIMUM QUALIFICATIONS Shared denotes whether a Contractor Resource may be responsible for that in addition to another identified. Contractor Required

More information

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM) The Intersection of Enterprise-wide Risk (ERM) and Business Continuity (BCM) Marc Dominus 2005 Protiviti Inc. EOE Agenda Terminology and Process Introductions ERM Process Overview BCM Process Overview

More information

The table below compares to the 2009 Essential Elements and the 2018 Enhanced Data Stewardship Elements

The table below compares to the 2009 Essential Elements and the 2018 Enhanced Data Stewardship Elements October 8, 2018 The Essential Elements of Accountability were developed by a multi-stakeholder group that met in Dublin Ireland as the Global Accountability Dialogue. The Essential Elements provided granularity

More information

6. IT Governance 2006

6. IT Governance 2006 6. IT Governance 2006 Introduction The Emerging Enterprise Model 3 p IT is an integral part of the business p IT governance is an integral part of corporate governance 4 Challenges for the IT IT gets more

More information

ISACA All Rights Reserved.

ISACA All Rights Reserved. Tichaona Zororo CIA, CISA, CISM, CRISC, CRMA, CGEIT, COBIT 5 Certified Assessor B.Sc. Honours Information Systems, PGD Computer Auditing Accredited COBIT 5 Trainer ISACA 2016. Business Value Value

More information

ISACA Systems Implementation Assurance February 2009

ISACA Systems Implementation Assurance February 2009 ISACA Pressures Today Pressure to increase realization of value from IT spending Pressure to deliver on IT projects at a time when resources/budgets are constrained Pressure from risk of technology-based

More information

Risk Management Culture: The Linkage Between Ethics & Compliance and ERM September 14, 2009

Risk Management Culture: The Linkage Between Ethics & Compliance and ERM September 14, 2009 2009 Compliance and Ethics Institute Risk Management Culture: The Linkage Between Ethics & Compliance and ERM September 14, 2009 Table of contents Section 1 2 3 4 5 6 Learning objectives Why measure risk

More information

Deloitte Governance Framework and Maturity Model

Deloitte Governance Framework and Maturity Model Deloitte Governance Framework and Maturity Model Deloitte Governance Framework The Deloitte Governance Framework was developed to help boards and executive management assess the effectiveness of the organization

More information

COSO ERM: Integrating with Strategy and Performance. Michael Parkinson

COSO ERM: Integrating with Strategy and Performance. Michael Parkinson COSO ERM: Integrating with Strategy and Performance Michael Parkinson Content The COSO Frameworks Risk (Enterprise) Risk Management The COSO risk management framework A few highlights Questions for management

More information

CGEIT ITEM DEVELOPMENT GUIDE

CGEIT ITEM DEVELOPMENT GUIDE CGEIT ITEM DEVELOPMENT GUIDE Updated March 2017 TABLE OF CONTENTS Content Page Purpose of the CGEIT Item Development Guide 3 CGEIT Exam Structure 3 Writing Quality Items 3 Multiple-Choice Items 4 Steps

More information

10 metrics for improving the level of management. Pekka Forselius, Senior Advisor, FiSMA ry Risto Nevalainen, Senior Advisor, FiSMA ry

10 metrics for improving the level of management. Pekka Forselius, Senior Advisor, FiSMA ry Risto Nevalainen, Senior Advisor, FiSMA ry 10 metrics for improving the level of management Pekka Forselius, Senior Advisor, FiSMA ry Risto Nevalainen, Senior Advisor, FiSMA ry Contents Introduction to selecting measures Classification of metrics

More information

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II S P E A K E R : D O T T. FA B I O A C C A R D I C O U R S E O F B U S I N E S S A U D I T I N G U N I V E R

More information

CGEIT QAE ITEM DEVELOPMENT GUIDE

CGEIT QAE ITEM DEVELOPMENT GUIDE CGEIT QAE ITEM DEVELOPMENT GUIDE TABLE OF CONTENTS PURPOSE OF THE CGEIT ITEM DEVELOPMENT GUIDE 3 PURPOSE OF THE CGEIT QAE... 3 CGEIT EXAM STRUCTURE... 3 WRITING QUALITY ITEMS... 3 MULTIPLE-CHOICE ITEMS...

More information

Business Benefits by Aligning IT best practices

Business Benefits by Aligning IT best practices Business Benefits by Aligning IT best practices Executive Summary Since the Sarbanes-Oxley Act (Sarbanes-Oxley or SOX) was signed into law in 2002, many companies have adopted some IT practices to comply

More information

Topics. Background Approach Status

Topics. Background Approach Status 16 th September 2014 Topics Background Approach Status Background e-governance in India National e-governance Plan 2006 31 Mission Mode Projects Quality Assurance in e-governance Quality Assessment of

More information

Road to Self Governance

Road to Self Governance Road to Self Governance Transform internal controls; sustain business performance 8 January 2015 Contents 1. Setting the Context 2. What needs to be done 3. Perspectives on IFC coverage 4. Leveraging IFC

More information

FROM ERP TO COBIT MOVING TOWARD MATURE OF- THE-SHELF INFORMATION SYSTEMS. A Toy Example A Small Detergent Manufacturing Co.

FROM ERP TO COBIT MOVING TOWARD MATURE OF- THE-SHELF INFORMATION SYSTEMS. A Toy Example A Small Detergent Manufacturing Co. FROM ERP TO COBIT MOVING TOWARD MATURE OF- THE-SHELF INFORMATION SYSTEMS Armin Shmilovici and Eli Rohn Department of Information Systems Engineering Ben-Gurion University, Israel {armin, elirohn}@bgu.ac.il

More information

Governance, COBIT and the Cloud a match made in the sky! Robert E Stroud CGEIT International Vice President ISACA Treasurer, Director Audit,

Governance, COBIT and the Cloud a match made in the sky! Robert E Stroud CGEIT International Vice President ISACA Treasurer, Director Audit, Governance, COBIT and the Cloud a match made in the sky! Robert E Stroud CGEIT International Vice President ISACA Treasurer, Director Audit, Standards & Compliance itsmf Intl. Service Management and Governance

More information

Changes Reviewed by Date. JO Technology Manager - Samer Huwwari JO Manager, Risk & Control Technology: Issa Laty. CIO, Jordan- Mohammad Aburoub

Changes Reviewed by Date. JO Technology Manager - Samer Huwwari JO Manager, Risk & Control Technology: Issa Laty. CIO, Jordan- Mohammad Aburoub Governance and Management of Information and Related Technologies Guide 2017 Revision History Changes Reviewed by Date Version Author JO Technology Manager - Samer Huwwari JO Manager, Risk & Control Technology:

More information

Service management. The future. Colin Rudd FBCS, CITP, CEng, FLPI, (Copenhagen September 2013)

Service management. The future. Colin Rudd FBCS, CITP, CEng, FLPI, (Copenhagen September 2013) management The future (Copenhagen September 2013) Colin Rudd FBCS, CITP, CEng, FLPI, Chairman itsmf UK Management consultant, mentor and coach ITIL Author IT Enterprise Management s Ltd. colin.rudd@itsmf.co.uk

More information

Sarbanes-Oxley: Company Case Study - Viacom Inc. IT General Controls - Sustaining Compliance Efforts. Anthony Noble VP, IT Internal Audit

Sarbanes-Oxley: Company Case Study - Viacom Inc. IT General Controls - Sustaining Compliance Efforts. Anthony Noble VP, IT Internal Audit Sarbanes-Oxley: A Focus on IT Controls Company Case Study - Viacom Inc. IT General Controls - Sustaining Compliance Efforts Anthony Noble VP, IT Internal Audit Today s Agenda Introduction Viacom Methodology

More information

Annex 1 (Integrated frameworks on Business/IT alignment) Annex 2 Goals Cascade, adapted from COBIT5

Annex 1 (Integrated frameworks on Business/IT alignment) Annex 2 Goals Cascade, adapted from COBIT5 Annex (Integrated frameworks on Business/IT alignment) Annex 2 Goals Cascade, adapted from COBIT5 Annex 2 RACI chart for EDM0, Retrieved from COBIT5 Description: R Responsible The one(s) who performs the

More information

Internal controls over Financial Reporting Key concepts. Presentation by Jayesh Gandhi at WIRC

Internal controls over Financial Reporting Key concepts. Presentation by Jayesh Gandhi at WIRC Internal controls over Financial Reporting Key concepts Presentation by Jayesh Gandhi at WIRC Page 1 ICFR Key Concepts WIRC 28 May 2016 Agenda Scope and requirements Overview of internal controls as per

More information

B U S I N E S S R I S K M A N A G E M E N T L T D

B U S I N E S S R I S K M A N A G E M E N T L T D B U S I N E S S R I S K M A N A G E M E N T L T D Governance, Risk and Compliance (GRC) After completing this course you will be able to Course Level Understand the requirements and benefits of GRC Develop

More information

TABLE OF CONTENTS 2. INFORMATION TECHNOLOGY IN A BUSINESS ENVIRONMENT 15

TABLE OF CONTENTS 2. INFORMATION TECHNOLOGY IN A BUSINESS ENVIRONMENT 15 . INTRODUCTION. INFORMATION TECHNOLOGY IN A BUSINESS ENVIRONMENT.. THE ORGANIZATION AS A SYSTEM...... Business processes...................................................... The value chain...... Value

More information

Modernizing compliance: Moving from value protection to value creation

Modernizing compliance: Moving from value protection to value creation Modernizing compliance: Moving from value protection to value creation John Conrad, Principal Deloitte Risk and Financial Advisory Deloitte & Touche LLP Clarissa Crain, Senior Manager Deloitte Risk and

More information

Statement on Risk Management and Internal Control

Statement on Risk Management and Internal Control INTRODUCTION The Board affirms its overall responsibility for the Group s system of internal control and risk management and for reviewing the adequacy and effectiveness of the system. The Board is pleased

More information

Risk Advisory Services Developing your organisation s governance for competitive advantage

Risk Advisory Services Developing your organisation s governance for competitive advantage Advisory Services Developing your organisation s governance for competitive advantage The Deloitte Advisory Platform of Services can help you to govern your strategic plan to guide your operations measure

More information

Enterprise Risk Management: Aligning Risk with Strategy & Performance June 26, :45 p.m. 4:45 p.m.

Enterprise Risk Management: Aligning Risk with Strategy & Performance June 26, :45 p.m. 4:45 p.m. Enterprise Risk Management: Aligning Risk with Strategy & Performance June 26, 2017 3:45 p.m. 4:45 p.m. Presented by: Marc Winkler Director P&G Associates 646 Highway 18 East Brunswick, NJ 08816 P: 877-651-1700

More information

Enterprise Digital Architect

Enterprise Digital Architect Enterprise Digital Architect Location: [Asia & Pacific] [Australia] Town/City: Preferred locations: Australia, USA, Malaysia or Manila; or any other jurisdiction (country or US state) where WVI is registered

More information

Appendix A. Simplified Sample Entity-Level Control Matrices

Appendix A. Simplified Sample Entity-Level Control Matrices Control Strategies: A Mid to Small Business Guide By Julie Harrer Copyright 2008 Hamlet ing Corp. Appendix A Simplified Sample Entity-Level Control Matrices Control Environment Possible Controls Integrity

More information

Community Bankers Conference

Community Bankers Conference 3rd Annual Regional and Community Bankers Conference The Federal Reserve Bank of Boston Disclaimer NEVER WRONG DON T COMPLETELY RELY UPON Recent Developments in Audit Practice SOX, FDICIA 112, Other Robert

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy 2017-2019 Created by: Role Name Title Author / Editor Kevin McMahon Head of Risk Management & Resilience Lead Executive Margo McGurk Director of Finance & Performance Approved

More information

RSA ARCHER IT & SECURITY RISK MANAGEMENT

RSA ARCHER IT & SECURITY RISK MANAGEMENT RSA ARCHER IT & SECURITY RISK MANAGEMENT INTRODUCTION Organizations battle growing security challenges by building layer upon layer of defenses: firewalls, anti-virus, intrusion prevention systems, intrusion

More information

Quick Guide: Meeting ISO Requirements for Asset Management

Quick Guide: Meeting ISO Requirements for Asset Management Please visit the NAMS.org.nz website for downloading the digital version of this quick guide. Supplement to the IIMM 2011 Quick Guide: Meeting ISO 55001 Requirements for Asset Management Using the International

More information

Internal Control Integrated Framework. An IAASB Overview September 2016

Internal Control Integrated Framework. An IAASB Overview September 2016 Internal Control Integrated Framework An IAASB Overview September 2016 0 Table of Contents COSO & Project Overview Internal Control-Integrated Framework Illustrative Documents Illustrative Tools for Assessing

More information

Internal Control Integrated Framework. An IAASB Overview September 2016

Internal Control Integrated Framework. An IAASB Overview September 2016 Internal Control Integrated Framework An IAASB Overview September 2016 0 Table of Contents COSO & Project Overview Internal Control-Integrated Framework Illustrative Documents Illustrative Tools for Assessing

More information

pwc.co.uk Enterprise Risk Management

pwc.co.uk Enterprise Risk Management pwc.co.uk Enterprise Risk Management Contents What s on your mind? 01 Our point of view 02 What good looks like 04 How we can help 06 What you gain 07 When to act 08 Intelligent Digital 09 What s on your

More information

What is ISO/IEC 20000?

What is ISO/IEC 20000? An Introduction to the International Service Management Standard By President INTERPROM September 2018 Copyright 2018 by InterProm USA. All Rights Reserved www.interpromusa.com Contents INTRODUCTION...

More information

Practices in Enterprise Risk Management

Practices in Enterprise Risk Management Practices in Enterprise Risk Management John Foulley Risk Management Practices Head SAS Institute Asia Pacific What is ERM? Enterprise risk management is a process, effected by an entity s board of directors,

More information

Fear, Uncertainty, Doubt

Fear, Uncertainty, Doubt Fear, Uncertainty, Doubt However, ERM = Manageable OK, Back to The Bonadio Group Standard Enterprise Risk Management An Overview on Key Controls We Will Cover Why ERM ERM COSO basics Tangible benefits

More information

Recognizing your needs

Recognizing your needs Our internal audit and IT risk assurance capability statement Recognizing your needs www.pwc.com/ph Our Assurance services Assurance PwC Assurance team delivers the assurance you need on the financial

More information

International Civil Aviation Organization FIRST INFORMATION MANAGEMENT PANEL (IMP/1) Montreal, Canada January, 25 30, 2015

International Civil Aviation Organization FIRST INFORMATION MANAGEMENT PANEL (IMP/1) Montreal, Canada January, 25 30, 2015 International Civil Aviation Organization WORKING PAPER 15/01/2015 rev. 0 FIRST INFORMATION MANAGEMENT PANEL (IMP/1) Montreal, Canada January, 25 30, 2015 Agenda Item 5: Review and elaborate on concepts,

More information

20 Years in the Making. Meet the New ICIF: Revisions to COSO s Internal Control Integrated Framework. Dr. Sandra Richtermeyer COSO Board Member

20 Years in the Making. Meet the New ICIF: Revisions to COSO s Internal Control Integrated Framework. Dr. Sandra Richtermeyer COSO Board Member Meet the New ICIF: Revisions to COSO s Internal Control Integrated Framework Dr. Sandra Richtermeyer COSO Board Member Associate Dean and Professor of Accountancy Xavier University Cincinnati Ohio USA

More information

Implementation of the CO BIT -3 Maturity Model in Royal Philips Electronics

Implementation of the CO BIT -3 Maturity Model in Royal Philips Electronics Implementation of the CO BIT -3 Maturity Model in Royal Philips Electronics Alfred C.E. van Gils Philips International BV Corporate Information Technology Eindhoven, The Netherlands Abstract: Philips has

More information

COBIT 5. COBIT 5 Online Collaborative Environment

COBIT 5. COBIT 5 Online Collaborative Environment COBIT 5 Product Family COBIT 5 Enabler Guides COBIT 5 COBIT 5: Enabling es COBIT 5: Enabling Information Other Enabler Guides COBIT 5 Professional Guides COBIT 5 Implementation COBIT 5 for Information

More information

ISO Standards in Strengthening Organizational Resilience, Mitigating Risk & Addressing Sustainability Concerns

ISO Standards in Strengthening Organizational Resilience, Mitigating Risk & Addressing Sustainability Concerns ISO Standards in Strengthening Organizational Resilience, Mitigating Risk & Addressing Sustainability Concerns 13 December 2016 Joe Muratore Copyright 2012 BSI. All rights reserved. Enterprise Risk Management

More information

Enterprise Risk Management Program Development Update. Finance & Audit Committee Meeting September 25, 2015

Enterprise Risk Management Program Development Update. Finance & Audit Committee Meeting September 25, 2015 Enterprise Risk Management Program Development Update Finance & Audit Committee Meeting September 25, 2015 Enterprise Risk Management Presentation Topics Enterprise Risk Management ( ERM ) Overview Lead

More information

Information Privacy and Cybersecurity in a King IV World

Information Privacy and Cybersecurity in a King IV World Information Privacy and Cybersecurity in a King IV World King IV The King IV Report on Corporate Governance for South Africa 2016, The Institute of Directors in Southern Africa. Released 1 November 2016

More information

The purpose of this document is to define the overall IT Strategy for the period 2016 to 2021

The purpose of this document is to define the overall IT Strategy for the period 2016 to 2021 Information Technology IT STRATEGY The purpose of this document is to define the overall IT Strategy for the period 2016 to 2021 The IT Strategy will align with the wider University Strategy. It will be

More information

Risk Management in Istat: from the project to the process

Risk Management in Istat: from the project to the process WORKSHOP ON RISK MANAGEMENT SYSTEMS AND PRACTICES Risk Management in Istat: from the project to the process Genève, 25-26 April 2016 Page 1 Management System Network Values and ethics Organizational culture

More information

International Standards for the Professional Practice of Internal Auditing (Standards)

International Standards for the Professional Practice of Internal Auditing (Standards) INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Attribute Standards 1000 Purpose, Authority, and Responsibility The purpose, authority, and responsibility of the

More information

A Vision of an ISO Compliant Company by Bruce Hawkins, MRG, Inc.

A Vision of an ISO Compliant Company by Bruce Hawkins, MRG, Inc. A Vision of an ISO 55000 Compliant Company by Bruce Hawkins, MRG, Inc. ISO 55000 refers to a series of three standards outlining the purpose, requirements, and implementation guidance for an Asset Management

More information

EVALUATION OF INFRASTRUCTURE INFORMATION TECHNOLOGY GOVERNANCE USING COBIT 4.1 FRAMEWORK

EVALUATION OF INFRASTRUCTURE INFORMATION TECHNOLOGY GOVERNANCE USING COBIT 4.1 FRAMEWORK International Conference on Information Systems for Business Competitiveness (ICISBC 2013) 20 EVALUATION OF INFRASTRUCTURE INFORMATION TECHNOLOGY GOVERNANCE USING COBIT 4.1 FRAMEWORK Rusmala Santi 1) Syahril

More information

Strengthening Your Enterprise Risk Management Process

Strengthening Your Enterprise Risk Management Process Strengthening Your Enterprise Risk Management Process Belinda Mumma, Senior Consultant, Enterprise Risk Management Services bmumma@sollievo.com (866) 605-5664 x3400 Discussion Topics Definition of Enterprise

More information

An Overview of the 2013 COSO Framework. August 2013

An Overview of the 2013 COSO Framework. August 2013 An Overview of the 2013 COSO Framework August 2013 Introduction Dean Geesler, KPMG Senior Manager Course Objectives Summarize the key changes from the 1992 Framework to the 2013 Framework including the

More information

CORROSION MANAGEMENT MATURITY MODEL

CORROSION MANAGEMENT MATURITY MODEL CORROSION MANAGEMENT MATURITY MODEL CMMM Model Definition AUTHOR Jeff Varney Executive Director APQC Page 1 of 35 TABLE OF CONTENTS OVERVIEW... 5 I. INTRODUCTION... 6 1.1 The Need... 6 1.2 The Corrosion

More information

INTERNAL CONTROLS ON OUR CAMPUS. Kara Kearney-Saylor Director of Internal Audit, UB

INTERNAL CONTROLS ON OUR CAMPUS. Kara Kearney-Saylor Director of Internal Audit, UB INTERNAL CONTROLS ON OUR CAMPUS Kara Kearney-Saylor Director of Internal Audit, UB 1 Select headlines over the past 12 months.. Dennis Black under investigation for UB spending Former UB VP Dennis Black

More information

Guidance Note: Corporate Governance - Audit Committee. March Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Audit Committee. March Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Audit Committee March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance Audit Committee (the Guidance Note )

More information

Guidance Note: Corporate Governance - Audit Committee. January Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Audit Committee. January Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Audit Committee January 2018 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance Audit Committee (the Guidance Note

More information

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad

Diving into the 2013 COSO Framework. Presented by: Ronald A. Conrad Diving into the 2013 COSO Framework Presented by: Ronald A. Conrad 2 Objectives Obtain an understanding of why the COSO Framework has been updated Understand how the framework has changed Identify the

More information

Washington Metropolitan Area Transit Authority Board Action/Information Summary

Washington Metropolitan Area Transit Authority Board Action/Information Summary Washington Metropolitan Area Transit Authority Board Action/Information Summary Action Information MEAD Number: 201804 Resolution: Yes No TITLE: Board Audit Awareness Training PRESENTATION SUMMARY: The

More information

ISO INTERNATIONAL STANDARD. Risk management Principles and guidelines. Management du risque Principes et lignes directrices

ISO INTERNATIONAL STANDARD. Risk management Principles and guidelines. Management du risque Principes et lignes directrices INTERNATIONAL STANDARD ISO 31000 First edition 2009-11-15 Risk management Principles and guidelines Management du risque Principes et lignes directrices http://mahdi.hashemitabar.com Reference number ISO

More information

Integrating COSO s Fraud Risk Management Guide on an Enterprise Scale

Integrating COSO s Fraud Risk Management Guide on an Enterprise Scale Integrating COSO s Fraud Risk Management Guide on an Enterprise Scale September 15, 2017 Vincent Walden Partner EY Atlanta Delores White Director, Internal Audit Southern Company Scott Hulsey Chief Compliance

More information

Quality Assurance and Improvement Program

Quality Assurance and Improvement Program Internal Audit Foundations Standards 1000, 1010, 1100, 1110, 1111, 1120, 1130, 1300, 1310, 1320, 1321, 1322, 2000, 2040 There is an Internal Audit Charter in place Internal Audit Charter is in place The

More information

Director Training and Qualifications

Director Training and Qualifications 4711 Yonge Street Suite 700 Toronto ON M2N 6K8 Telephone: 416-325-9444 Toll Free 1-800-268-6653 Fax: 416-325-9722 4711, rue Yonge Bureau 700 Toronto (Ontario) M2N 6K8 Téléphone : 416 325-9444 Sans frais

More information

Technology s Role in Enterprise Risk Management

Technology s Role in Enterprise Risk Management FEATURE Technology s Role in Enterprise Risk Management www.isaca.org/currentissue The new COSO ERM framework document, Enterprise Risk Management Integrating With Strategy and, 1 is expected to have a

More information

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it?

Sarbanes-Oxley Act of 2002 Can private businesses benefit from it? Sarbanes-Oxley Act of 2002 Can private businesses benefit from it? As used in this document, Deloitte means Deloitte Tax LLP, which provides tax services; Deloitte & Touche LLP, which provides assurance

More information

Advisory Services Governance, Risk & Compliance

Advisory Services Governance, Risk & Compliance Advisory Services Governance, Risk & Compliance Caribbean Association of Audit Committee Members Inc. 2010 Conference Caretakers of Integrity and Accountability: The Role of Internal Audit in Corporate

More information

Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting

Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting July 17, 2017 Objectives Provide perspective on the evolution of Enterprise Risk Management (ERM) New 2017

More information

Implementation Tool for Auditors

Implementation Tool for Auditors Implementation Tool for Auditors CANADIAN AUDITING STANDARDS (CAS) DECEMBER 2017 STANDARD DISCUSSED CAS 315, Identifying and Assessing the Risks of Material Misstatement through Understanding the Entity

More information

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER ARRIVAL OF GDPR IN 2018 The European Union (EU) General Data Protection Regulation (GDPR), which takes effect in 2018, will bring changes

More information

INTERNAL AUDIT PLAN AND CHARTER 2018/19

INTERNAL AUDIT PLAN AND CHARTER 2018/19 INTERNAL AUDIT PLAN AND CHARTER 208/9 PURPOSE OF REPORT. To present the proposed 208/9 audit plan and charter to the Audit Committee for consideration and approval..2 The Internal Audit Plan for 208/9

More information

Risk Management Policy

Risk Management Policy Risk Management Policy 2015 Steadfast Group Limited ABN: 98 073 659 677 Risk Management Policy 1 ABN: 98 073 659 677 2013 Steadfast Group Limited Contents 1. INTRODUCTION 2 2. POLICY INTENT 2 3. POLICY

More information

VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIVERSITY COMPLIANCE, AUDIT, AND RISK COMMITTEE OF THE BOARD OF VISITORS COMPLIANCE, AUDIT, AND RISK CHARTER

VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIVERSITY COMPLIANCE, AUDIT, AND RISK COMMITTEE OF THE BOARD OF VISITORS COMPLIANCE, AUDIT, AND RISK CHARTER VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIVERSITY COMPLIANCE, AUDIT, AND RISK COMMITTEE OF THE BOARD OF VISITORS I. PURPOSE COMPLIANCE, AUDIT, AND RISK CHARTER The primary purpose of the Compliance,

More information

Braindumps COBIT5 50q

Braindumps COBIT5 50q Braindumps COBIT5 50q Number: COBIT5 Passing Score: 800 Time Limit: 120 min File Version: 16.5 http://www.gratisexam.com/ Isaca COBIT 5 COBIT 5 Foundation I have correct many of questions answers. If there

More information

DIRECTOR TRAINING AND QUALIFICATIONS: SAMPLE SELF-ASSESSMENT TOOL February 2015

DIRECTOR TRAINING AND QUALIFICATIONS: SAMPLE SELF-ASSESSMENT TOOL February 2015 DIRECTOR TRAINING AND QUALIFICATIONS: SAMPLE SELF-ASSESSMENT TOOL February 2015 DIRECTOR TRAINING AND QUALIFICATIONS SAMPLE SELF-ASSESSMENT TOOL INTRODUCTION The purpose of this tool is to help determine

More information

UoD IT Job Description

UoD IT Job Description UoD IT Job Description Role: Service Delivery Manager (People HERA Grade: 8 Management Systems) Responsible to: Assistant Director (Business Services) Accountable for: Day to day leadership of team members

More information

Regulatory Reporting: Implementing the proposed MAS Notice 610. Navigating the regulatory reporting and data challenge

Regulatory Reporting: Implementing the proposed MAS Notice 610. Navigating the regulatory reporting and data challenge Regulatory Reporting: Implementing the proposed MAS Notice 610 Navigating the regulatory reporting and data challenge Contents 03 Introduction 04 MAS Notice 610 timeline and implementation 05 Addressing

More information

Internal Financial Controls (IFC) ICAI Seminar October 8, 2016

Internal Financial Controls (IFC) ICAI Seminar October 8, 2016 Internal Financial Controls (IFC) 1 ICAI Seminar October 8, 2016 Financial Reporting Assertions 3 Effective Internal Controls over Financial Reporting All Significant Accounts considered Minor or few internal

More information

STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL

STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL STATEMENT ON RISK MANAGEMENT AND INTERNAL CONTROL FINANCIAL YEAR ENDED 31 DECEMBER 2017 INTRODUCTION The Board of Directors is pleased to provide the Statement on Risk Management and Internal Control pursuant

More information

ASSESSMENT AND EVALUATION OF THE CITY OF PHILADELPHIA S INFORMATION TECHNOLOGY GENERAL CONTROLS FISCAL 2016

ASSESSMENT AND EVALUATION OF THE CITY OF PHILADELPHIA S INFORMATION TECHNOLOGY GENERAL CONTROLS FISCAL 2016 ASSESSMENT AND EVALUATION OF THE CITY OF PHILADELPHIA S INFORMATION TECHNOLOGY GENERAL CONTROLS FISCAL 2016 Charles J. Brennan Chief Information Officer Office of Innovation and Technology 1234 Market

More information

If It s not a Business Initiative, It s not COBIT 5

If It s not a Business Initiative, It s not COBIT 5 If It s not a Business Initiative, It s not COBIT 5 Steve Romero CISSP PMP CPM Romero Consulting Core Competencies C22 CRISC CGEIT CISM CISA 1 9/13/2013 1 COBIT Page 11 COBIT 5 product family 2 COBIT Page

More information

Executive Summary THE OFFICE OF THE INTERNAL AUDITOR. Committee Meeting, June 19, 2017 Board of Governors Meeting, June 20, 2017.

Executive Summary THE OFFICE OF THE INTERNAL AUDITOR. Committee Meeting, June 19, 2017 Board of Governors Meeting, June 20, 2017. THE OFFICE OF THE INTERNAL AUDITOR 1 Page The Office of Internal Audit focuses its attention on areas where it can contribute the most by working with the organization to reduce risk and increase operational

More information

9/17/2017. An Overview of COSO s New Framework and Implementation Guidance SPEAKER. Laura Harden, CPA History

9/17/2017. An Overview of COSO s New Framework and Implementation Guidance SPEAKER. Laura Harden, CPA History An Overview of COSO s New Framework and Implementation Guidance SPEAKER Laura Harden, CPA lharden@cbh.com History 2 1 About COSO Committee of Sponsoring Organizations Formed in 1985 to sponsor the National

More information